Medium severity4.3NVD Advisory· Published Jul 8, 2026· Updated Jul 13, 2026
CVE-2026-58214
CVE-2026-58214
Description
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an authenticated MQTT client could subscribe to the internal $MQTT.deliver.pubrel subject family, bypassing configured subscribe permissions and exposing MQTT QoS2 protocol metadata for sessions in the account. This issue is fixed in versions 2.14.3 and 2.12.12.
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/nats-io/nats-server/commit/297b166be60fe13144084eed4b25201ead03204anvdPatch
- github.com/nats-io/nats-server/commit/34b09657bb596d5f850eaa5cfc97ea6b2f989a97nvdPatch
- github.com/nats-io/nats-server/security/advisories/GHSA-4g68-3pwx-5vfjnvdVendor Advisory
- github.com/nats-io/nats-server/releases/tag/v2.12.12nvdRelease Notes
- github.com/nats-io/nats-server/releases/tag/v2.14.3nvdRelease Notes
News mentions
0No linked articles in our index yet.